Uploaded image for project: 'OpenShift Cloud'
  1. OpenShift Cloud
  2. OCPCLOUD-2277

Ensure Cluster Machine Approver metrics are only available via HTTPS

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Critical Critical
    • None
    • None
    • CLOUD Sprint 245

      Background

      CMA currently exposes metrics on two ports via the 0.0.0.0 all hosts binding. We need to make sure that only the TLS port is accessible from outside localhost.

      Steps

      • Move the binding for the local metrics server to localhost only
      • Ensure kube-rbac-proxy is still proxying the requests over TLS

      Stakeholders

      • Cluster Infra
      • Subin M

      Definition of Done

      • Metrics from CMA are only exposed over TLS
      • Docs
      • <Add docs requirements for this card>
      • Testing
      • <Explain testing that will be added>

              raryan@redhat.com Rachel Ryan
              joelspeed Joel Speed
              Milind Yadav Milind Yadav
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: